[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1911-1] exim4 security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : exim4
Version        : 4.84.2-2+deb8u6
CVE ID         : CVE-2019-15846


"Zerons" and Qualys discovered that a buffer overflow triggerable in the
TLS negotiation code of the Exim mail transport agent could result in the
execution of arbitrary code with root privileges.


For Debian 8 "Jessie", this problem has been fixed in version
4.84.2-2+deb8u6.

We recommend that you upgrade your exim4 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl1yNyRfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEeDHBAAsTIcEg9+pytEspkf5NuPyvcJK9zh4uiHj6ONTudl+HDUSAt3e+4h7iAK
gqWXjyorvevZ8Tf6OkxWxNFV3AiBWiVzH6Qo5/urCz1fogSuJQKj8wTjgp8voM8F
hfcLOP9UYEEAMnWQtZRAaTt9WbkGcgzXukhyv8yfR6yCwxiKycP99qvPWtAifJhN
idXLx8EE7P6m8s4c4HW+9soGyEW1/Jl2XR210VIZhN1gpT9EHlm5aH4FGm8dedGB
Tpfa8m0B+AOAAaaNuv9XExXSVDlaYCHt308EIAgn2j0OfXAPQQROp5Ps8n8UJCAC
IYYD8eAI8g686DON16PIzgfzuvbPXudxQnxH9347MUGOwXm9eFazgM/g+NExxyL8
HVQsSwaUT3XF9sfdXnTCvf/d04wqyRdwzwNpCi8VzwBRAo3zqixvd1YTaBbhk+Rq
nBYwPUJcqquNzJ8lW71XnXT407hoB9B57iolAbi6H86G1/sWESgGfHG/Z7/VvdGu
xj9i0vwip9UnSdpTSDXzrEaTAGRK2JEFUiGPHtEAJYAebMDI4aRKlJ05k8+7oCbD
7NxcwvAf9OWhdJD9rwrd6BTrEDbolxdz/e1Mk4rVZt48XnMLmaTxpoKIPsiO6Yvg
X2+W3jPPQ2Cd7ORSaH6tLoZjTdCA2eR6TUqI925XjSbQCupf0aM=
=8NPw
-----END PGP SIGNATURE-----


Reply to: